The EU AI Act for Hiring Teams: What Applies From August 2026
Recruitment AI is classified as high-risk under the EU AI Act, and the deployer obligations are aimed at the teams that use these tools, not just the vendors that build them. What Article 26 actually asks of a recruiting team, where the August 2026 date stands, and a practical preparation list.
Cet article n’est pas encore traduit en français. La version anglaise est affichée ci-dessous.

If your team uses AI anywhere in hiring, to filter applications, score resumes, rank candidates, or evaluate video answers, the EU AI Act treats that tool as a high-risk AI system, and it assigns obligations to you, not only to the vendor who built it. Most of the coverage of the Act is written for AI companies. This article is written for the people who deploy the tools: recruiters, talent acquisition leads, and HR teams hiring in the EU.
One thing before anything else: this is orientation, not legal advice. The Act interacts with GDPR, national labor law, and collective agreements in ways that depend on your situation. Use this to arrive at the counsel conversation prepared, not to skip it.
Why recruitment AI is high-risk
The EU AI Act (Regulation 2024/1689) sorts AI systems into risk tiers. Annex III, point 4 places employment squarely in the high-risk tier: AI systems intended for "the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates," plus systems used for decisions on promotion, termination, task allocation, or monitoring worker performance.
That is not a fringe category. If a tool reads applications and influences who advances, it is in scope. And the Act reaches beyond the EU's borders: it can apply to organizations outside the EU where the system's output is used inside it.
Provider or deployer: know which one you are
The Act splits duties between two roles:
- A provider develops the system and places it on the market. Providers carry the heavy obligations: risk management, data governance, technical documentation, conformity assessment, and designing the system for human oversight (Articles 9 to 15).
- A deployer uses the system under its own authority. A recruiting team running a screening tool is a deployer, and deployer duties live mainly in Article 26.
One trap worth knowing (Article 25): a deployer that puts its own name on a high-risk system, or substantially modifies one, becomes a provider and inherits the full provider burden. If you white-label or rework a screening tool, raise it with counsel before assuming you are "just" a deployer.
What already applies today
Two parts of the Act have been live since February 2, 2025:
- Prohibited practices (Article 5). Most relevant to hiring: AI that infers emotions in the workplace is banned, with narrow medical and safety exceptions. If any tool in your stack claims to read a candidate's emotional state from video or voice, that is not a compliance detail, it is a prohibited practice.
- AI literacy (Article 4). Providers and deployers must take measures to ensure their staff have a sufficient level of AI literacy. For a recruiting team, that means the people using an AI tool should understand what it does, what it cannot do, and how to interpret its output.
Where the August 2026 date stands
As written, the full high-risk regime for Annex III systems, including the Article 26 deployer obligations, applies from August 2, 2026.
That date has moved. The European Commission proposed the Digital Omnibus on AI in November 2025, negotiators reached a provisional agreement on May 7, 2026, the European Parliament approved it on June 16, and the Council formally adopted it on June 29, 2026, deferring the Annex III high-risk obligations to December 2, 2027.
One procedural step is still outstanding as this article goes out: publication in the Official Journal, after which the amendment enters into force three days later. Until that happens the original calendar is technically still the text in force, which is why the procedure was compressed to finish ahead of August 2. The practical posture for a hiring team: plan against December 2027, and do not treat August 2026 as formally displaced until the Official Journal entry appears.
Two things do not change either way: recruitment AI stays classified as high-risk, and the prohibitions and literacy duties above are already in force. A deferral moves the deadline; it does not un-ring the bell.
The deployer obligations, in plain terms
Article 26 is short by regulation standards. Here is what it asks of a team using a high-risk hiring tool, paragraph by paragraph:
- Use the system according to its instructions (26(1)). The provider must supply instructions for use; you must put technical and organizational measures in place to follow them. Practical translation: someone on your team has actually read the vendor's documentation, and your process reflects it.
- Assign human oversight to real, competent people (26(2)). Oversight goes to named people with the training, authority, and support to intervene, not to "the team" in the abstract.
- Watch your input data (26(4)). To the extent you control the inputs, they must be relevant and sufficiently representative for the system's purpose. A job description full of requirements you do not actually mean is an input-data problem as well as a hiring problem.
- Monitor and report (26(5)). Monitor the system's operation, and inform the provider and authorities of serious risks or incidents.
- Keep the logs (26(6)). Logs automatically generated by the system, where under your control, must be kept at least six months, subject to data protection law.
- Tell your workers (26(7)). Before putting a high-risk AI system into service in the workplace, employers must inform affected workers and their representatives.
- Tell the people it evaluates (26(11)). Candidates must be informed that a high-risk AI system is used on them.
- Feed your DPIA (26(9)). Where GDPR requires a data protection impact assessment, use the provider's documentation to do it.
Alongside Article 26 sits Article 86: a person affected by a decision with legal or similarly significant effects, made on the basis of a high-risk system's output, can request a clear and meaningful explanation of the role the AI played. A rejected candidate asking "what did the AI actually do in my case?" is a request your process needs to be able to answer.
One obligation most private employers do not carry: the fundamental rights impact assessment in Article 27 applies to public bodies, private entities providing public services, and certain credit and insurance use cases. Confirm your position with counsel, but a typical private hiring team is outside it.
The stakes are real. Non-compliance with deployer obligations can draw fines up to 15 million euros or 3 percent of worldwide annual turnover; prohibited practices go up to 35 million euros or 7 percent, with proportionality provisions for smaller companies.
A preparation list you can start this week
- Inventory. List every tool in your hiring flow that uses AI, including features inside tools you think of as databases.
- Collect vendor documentation. Ask each vendor for the instructions for use and technical documentation the Act requires of providers. A vendor that cannot produce them is telling you something.
- Name an oversight owner. One person per tool, with training and the explicit authority to override or halt it.
- Check what the tool logs, and keep it. Confirm what is retained, where, and for how long.
- Draft the two notifications. One for workers and their representatives, one for candidates. Plain language beats boilerplate in both.
- Write your explanation playbook. Decide today how you would answer a candidate who asks what role AI played in their evaluation. If your current tool cannot support an answer, that is a selection criterion for your next one.
- Book the counsel conversation. Bring the inventory and the vendor documents.
Where a screening tool fits into this
Several deployer duties come down to one question: can your tool show its work? Talentino is built around mechanisms that align with that question. Every score comes with a per-requirement breakdown and evidence quoted from the resume itself, which gives you concrete material when a candidate or a hiring manager asks why a decision went the way it did. Scoring is deterministic: same resume, same job, same score, every run, so an evaluation can be reproduced rather than argued about. And every status change is recorded in an audit trail, so who decided what, and when, is a record instead of a memory.
To be direct about the limits: no screening tool makes you compliant, and you should be skeptical of any vendor that claims theirs does. Compliance under the AI Act is a property of your whole process: your oversight, your notifications, your records, your counsel's review. What a tool can honestly do is make the evidence-and-records part of that process something you already have instead of something you scramble to produce. Start free and see what evidence-backed screening looks like on a real role, or book a demo and bring your compliance questions with you.